CVE-2025-25288
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 14, 2025
CWE ID 1333
Summary
CVE-2025-25288 is a vulnerability affecting the `@octokit/plugin-paginate-rest` package, used for paginating responses from the Octokit REST API. Versions prior to 11.4.1 are susceptible to a ReDoS (Recursive Denial of Service) attack. A malicious `link` parameter in the `headers` section of the `request` can be exploited by a specially crafted `octokit` instance, leading to excessive resource consumption and potential denial of service. The vulnerability has been addressed in version 11.4.1, which includes a fix for the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share